CVE-2025-65622: XSS
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 8.3.4 - Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65622?
CVE-2025-65622 has a low severity rating due to its impact being limited to stored cross-site scripting (XSS) via a specific field.
How do I fix CVE-2025-65622?
To fix CVE-2025-65622, upgrade Snipe-IT to version 8.3.4 or later to eliminate the vulnerability.
Who is affected by CVE-2025-65622?
CVE-2025-65622 affects users of Snipe-IT versions prior to 8.3.4, specifically through the Locations 'Country' field.
What kind of attack does CVE-2025-65622 allow?
CVE-2025-65622 allows attackers to execute stored cross-site scripting (XSS) via injected JavaScript in the 'Country' field.
Can low-privileged users exploit CVE-2025-65622?
Yes, low-privileged authenticated users can exploit CVE-2025-65622 to inject malicious scripts that could execute in the context of other users.